Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-32084

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809, Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 11 version 22H3, Windows Server 2012 (Server Core installation), Windows Server 2012, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 Version 23H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32083

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2012, Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2016, Windows Server 2025, Windows 11 Version 23H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 25H2, Windows 11 version 22H3
Provider severity
HIGH
Conflicts
1

CVE-2026-32082

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012, Windows 11 version 22H3, Windows Server 2025, Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows Server 2016, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2012 R2, Windows 10 Version 21H2, Windows 10 Version 1607, Windows Server 2019, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-32081

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 22H3, Windows Server 2022, Windows Server 2016, Windows Server 2025, Windows 10 Version 1809, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 24H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32080

Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-3208

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all versions up to, and including, 8.7.11. This makes it possible for unauthenticated attackers to retrieve PIX payment QR code images for arbitrary orders. PIX QR codes contain sensitive merchant information including PIX keys (which may be CPF/CNPJ personal identifiers), transaction amounts, merchant name

PUBLISHED
Vendor
mercadopago
Product
Mercado Pago payments for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32079

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2022, Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1607, Windows 11 Version 24H2, Windows 10 Version 1809, Windows 11 version 22H3, Windows Server 2019, Windows Server 2025, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows 11 Version 23H2, Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32078

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 10 Version 1809, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 26H1, Windows 11 version 22H3, Windows Server 2025, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-32077

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows Server 2012 (Server Core installation), Windows 11 Version 23H2, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012, Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-32076

Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows 11 Version 25H2, Windows Server 2025, Windows 11 Version 24H2, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-32075

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows 11 version 22H3, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2, Windows 10 Version 1607, Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows Server 2019, Windows Server 2012, Windows Server 2016 (Server Core installation), Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-32074

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2019, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025, Windows Server 2022, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-32073

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2025, Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 1607, Windows Server 2012, Windows Server 2022, Windows 11 version 22H3, Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-32072

Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows 11 Version 23H2, Windows 10 Version 1607, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2016, Windows 10 Version 21H2, Windows 11 version 22H3, Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32071

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2022, Windows 10 Version 22H2, Windows 10 Version 1809, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-32070

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows 11 Version 23H2, Windows 11 version 22H3, Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2012 R2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1607, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2012, Windows Server 2016, Windows Server 2012 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-3207

Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.

PUBLISHED
Vendor
TIBCO
Product
TIBCO BPM Enterprise
Provider severity
HIGH
Conflicts
0

CVE-2026-32069

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 21H2, Windows Server 2022, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 22H3
Provider severity
HIGH
Conflicts
1

CVE-2026-32068

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows 11 version 22H3, Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 11 Version 24H2, Windows 11 Version 23H2, Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2025, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2026-32067

OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy that allows attackers to reuse pairing approvals across multiple accounts. An attacker approved as a sender in one account can be automatically accepted in another account in multi-account deployments without explicit approval, bypassing authorization boundaries.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
LOW
Conflicts
1

CVE-2026-32065

OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered command text is used as approval identity while trimming argv token whitespace, but runtime execution uses raw argv. An attacker can craft a trailing-space executable token to execute a different binary than what the approver displayed, allowing unexpected command execution under the OpenClaw runtime user when they can influence command argv and reuse an approval context.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32064

OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to observe or interact with the sandbox browser without credentials.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32063

OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generation where attacker-controlled environment values are not validated for CR/LF characters, allowing newline injection to break out of Environment= lines and inject arbitrary systemd directives. An attacker who can influence config.env.vars and trigger service install or restart can execute arbitrary commands with the privileges of the OpenClaw gateway service user.

PUBLISHED
Vendor
openclaw
Product
openclaw
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-32062

OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, but not including, 2026.2.22 accept media-stream WebSocket upgrades before stream validation, allowing unauthenticated clients to establish connections. Remote attackers can hold idle pre-authenticated sockets open to consume connection resources and degrade service availability for legitimate streams.

PUBLISHED
Vendor
openclaw, openclaw
Product
voice-call, openclaw
Provider severity
HIGH
Conflicts
2

CVE-2026-32061

OpenClaw versions prior to 2026.2.17 contain a path traversal vulnerability in the $include directive resolution that allows reading arbitrary local files outside the config directory boundary. Attackers with config modification capabilities can exploit this by specifying absolute paths, traversal sequences, or symlinks to access sensitive files readable by the OpenClaw process user, including API keys and credentials.

PUBLISHED
Vendor
openclaw
Product
openclaw
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32060

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configured workspace directory. When apply_patch is enabled without filesystem sandbox containment, attackers can exploit crafted paths including directory traversal sequences or absolute paths to escape workspace boundaries and modify arbitrary files.

PUBLISHED
Vendor
openclaw
Product
openclaw
Provider severity
HIGH
Conflicts
1

CVE-2026-3206

Improper Resource Shutdown or Release vulnerability in KrakenD, SLU KrakenD-CE (CircuitBreaker modules), KrakenD, SLU KrakenD-EE (CircuitBreaker modules). This issue affects KrakenD-CE: before 2.13.1; KrakenD-EE: before 2.12.5.

PUBLISHED
Vendor
KrakenD, KrakenD
Product
KrakenD-EE, KrakenD-CE
Provider severity
LOW
Conflicts
1

CVE-2026-32059

OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allowing attackers to bypass denied-flag checks via abbreviated options. Remote attackers can execute sort commands with abbreviated long options to skip approval requirements in allowlist mode.

PUBLISHED
Vendor
openclaw
Product
openclaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32058

OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of previously approved requests with modified environment variables. Attackers with access to an approval id can exploit this by reusing an approval with changed env input, bypassing execution-integrity controls in approval-enabled workflows.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
LOW
Conflicts
1

CVE-2026-32057

OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pairing mechanism that accepts client.id=control-ui without proper device identity verification. An authenticated node role websocket client can exploit this by using the control-ui client identifier to skip pairing requirements and gain unauthorized access to node event execution flows.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-32056

OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attackers to bypass command allowlist protections. Remote attackers can inject malicious startup files such as .bash_profile or .zshenv to achieve arbitrary code execution before allowlist-evaluated commands are executed.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32055

OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files outside the workspace through in-workspace symlinks pointing to non-existent out-of-root targets. The vulnerability exists because the boundary check improperly resolves aliases, permitting the first write operation to escape the workspace boundary and create files in arbitrary locations.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32054

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local attackers to escape the managed temp root directory. An attacker with local access can create symlinks to route file writes outside the intended temp directory, enabling arbitrary file overwrite on the affected system.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32053

OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized event IDs are randomized per parse, allowing replay events to bypass manager dedupe checks. Attackers can replay Twilio webhook events to trigger duplicate or stale call-state transitions, potentially causing incorrect call handling and state corruption.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32052

OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidden commands by injecting positional argv carriers after inline shell payloads. Attackers can craft misleading approval text while executing arbitrary commands through trailing positional arguments that bypass display context validation.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32051

OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including gateway and cron through agent runs in scoped-token deployments. Attackers with write-scope access can perform control-plane actions beyond their intended authorization level by exploiting inconsistent owner-only gating during agent execution.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32050

OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling that allows unauthorized senders to enqueue status events before authorization checks are applied. Attackers can exploit the reaction-only event path in event-handler.ts to queue signal reaction status lines for sessions without proper DM or group access validation.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-32049

OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple channel ingestion paths. Remote attackers can send oversized media payloads to trigger elevated memory usage and potential process instability.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32048

OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to create child processes under unsandboxed agents. An attacker with a sandboxed session can exploit this to spawn child runtimes with sandbox.mode set to off, bypassing runtime confinement restrictions.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32046

OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by exploiting renderer-side vulnerabilities without requiring a sandbox escape. Attackers can leverage the disabled OS-level sandbox protections in the Chromium browser container to achieve code execution on the host system.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32045

OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and password requirements. Attackers on trusted networks can exploit this misconfiguration to access HTTP gateway routes without proper authentication credentials.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-32044

OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on other archive formats. Attackers can craft malicious tar.bz2 skill archives to bypass special-entry blocking and extracted-size guardrails, causing local denial of service during skill installation.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32043

OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run execution where the cwd parameter is validated at approval time but resolved at execution time. Attackers can retarget a symlinked cwd between approval and execution to bypass command execution restrictions and execute arbitrary commands on node hosts.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32042

OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including operator.admin. Attackers with valid shared gateway authentication can present a self-signed unpaired device identity to request and obtain higher operator scopes before pairing approval is granted.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32041

OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain accessible without authentication. Local processes or loopback-reachable SSRF paths can exploit this to access browser-control routes including evaluate-capable actions without valid credentials.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-32040

OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows attackers to execute arbitrary javascript by injecting malicious mimeType values in image content blocks. Attackers can craft session entries with specially crafted mimeType attributes that break out of the img src data-URL context to achieve cross-site scripting when exported HTML is opened.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-3204

Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL.

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32039

OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers to inherit elevated tool permissions through identifier collision attacks. Attackers can exploit untyped sender keys by forcing collisions with mutable identity values such as senderName or senderUsername to bypass sender-authorization policies and gain unauthorized access to privileged tools.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32038

OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to join another container's network namespace. Attackers can configure the docker.network parameter with container:<id> values to reach services in target container namespaces and bypass network hardening controls.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
CRITICAL
Conflicts
1

CVE-2026-32037

OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts allowlists during MSTeams media downloads. Attackers can supply or influence attachment URLs to force redirects to non-allowlisted targets, bypassing SSRF boundary controls.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
LOW, MEDIUM
Conflicts
1